WEEK 01

Cybersecurity Foundations & Ethics

Operational scenario

A fictional regional manufacturer, Carrollton Precision Works, is standing up its first security team. You are the newest hire and must set up the training lab safely before anyone touches a tool.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 1; acronym quiz 1
Deliverable: Signed agreement + lab inventory
Learning objectives
  • Define CIA, AAA, least privilege, defense-in-depth and zero trust
  • State the legal and ethical limits of security testing
  • Build and label an isolated lab LAN
Classroom topics
  • Threats vs. vulnerabilities vs. risk
  • Policies, standards and baselines
  • Career pathways
  • Professional ethics
Standards · vocabulary
NIST CSF 2.0 (Govern)ISO 31000
CIAAAAMFAGRCAPTIOC
Open glossary
Competency demonstrated: States security fundamentals and ethical boundaries.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Build and label a small isolated lab LAN; inventory every asset.

~2 h
Docker container lab

Lab 1 — Launch, stop, inspect and reset a guided workstation container.

~0.5 h
AR/VR immersive scenario

OSI / network orientation walkthrough. Role: Help-desk technician.

No headset? Guided slideshow + printed OSI map. Printed and mobile versions are also available.

Individual technical assignment

Write your personal lab safety & authorization statement.

Team exercise

Draft a one-page team charter and lab ground rules.

Required hardware
  • Managed switch or small router
  • Patch cables
  • Lab workstation
Required software
  • Docker Desktop / Engine + Compose
  • Text editor
Workplace application

Every security role begins with written authorization and an accurate asset inventory — you can't protect what you haven't listed.

Docker progression step
L1 Launching, stopping, inspecting and resetting containers

Bring up student-ws, stop it, inspect it, then reset the range and confirm a clean state.

L13 Segmenting IT and OT container networks

Verify ot-control is reachable only via idmz; document the path and the block.

L14 Testing approved firewall and access-control rules

Test each ACL rule for allow and deny; record the evidence pair.

L15 Investigating a simulated IT-to-OT intrusion

Trace the pivot from webapp → jump → historian → plc-sim; build the timeline.

L16 Restoring the environment and validating remediation

Restore from snapshot, apply remediation, and re-run steps 4, 12 and 15 to prove closure.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Governance & risk oversightAsset inventory & managementRisk assessment
See the full crosswalk